Impact
The vulnerability is a missing authentication flaw (CWE-306) that allows an attacker with local network access to spoof both student and teacher endpoints in WeenyGenius. Without needing credentials, the attacker can impersonate a student to disrupt normal classroom activities, or impersonate a teacher to trigger student computers to open connections, thereby enabling remote control of those endpoints.
Affected Systems
The vulnerability affects Howyar Technologies’ WeenyGenius computer lab management system on all versions released before 12.3.033. Users of earlier builds running on local networks are at risk.
Risk and Exploitability
With a CVSS score of 8.7, this flaw represents a high severity weakness. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The vulnerability can be exploited by a local network attacker with no authentication, allowing direct impersonation of users and remote control of endpoints. The lack of authentication makes it straightforward once the attacker gains network access.
OpenCVE Enrichment